UNSOLVED

Bruce-VZ

updated

10 years ago

BV

Bruce-VZ

3 Posts

0

21465

August 9th, 2016 16:00

Disabling TLSv1.0 on iDRAC 6, 7, 8 web interface

I am attempting to limit the iDRAC web interface traffic to use only TLSv1.2 per both internal security and PCI security requirements. I have searched and searched for a method to restrict web traffic to this protocol, but without success.


I have upgraded the iDRAC software (and rebooted) to iDRAC 6 2.85 and iDRAC7/8 2.30.30.30, but still find TLSv1.0 still enabled.

Additionally, I have tried to up the SSL ciphers option in the iDRAC configuration area to the highest permitted cipher levels in hopes that this might trigger higher SSL protocol usage in web interface. This was not successful.

Is there a configuration file or setting I can change in either via the web interface or RACADM command to disable TLSv1.0 and keep TLSv1.2 enabled?

Or will there be another patch/upgrade of iDRAC 6/7/8 that I can apply to do the same?

Thank you for your feedback!